Linux Dirty Frag Chain Roots Systems
Linux kernel just shipped another local root pipe weeks after Copy Fail. Attackers chain page cache writes to escalate from unprivileged user to root.
Dubbed Dirty Frag, CVE-2026-43284 and CVE-2026-43500 deliver 4-byte store primitives via xfrm-ESP and RxRPC sockets. CVSS 7.8. A public single-command PoC exploit is already available on GitHub.
Hits kernels since 2017 across Ubuntu 24.04, RHEL 10, Fedora 44, AlmaLinux 10, openSUSE, CentOS Stream 10. Works even with Copy Fail mitigations.
Single-command exploit published May 8, 2026.
